Legal
Ovuge Privacy Policy
Last Updated: August 2026
Welcome to Ovuge. We are committed to protecting your privacy and ensuring that your personal data is handled securely, transparently, and in accordance with applicable data protection laws (including GDPR and CCPA principles).
This Privacy Policy explains how we collect, use, store, and protect your information when you use the Ovuge website, application, and platform (collectively, the "Platform"). We do not, and will never, sell your personal data to third parties.
1. Information We Collect
We only collect the data necessary to operate the Platform, verify your identity, and provide our core features (project hosting, collaboration, and networking).
A. Information You Provide Directly
- Account Information: When you register, we collect your display name, username, and profile picture (avatar).
- Institutional Verification: If you choose to verify your account for a specific organizational Network, we collect your organizational email address (e.g., a .edu domain). This email is used strictly for issuing a one-time verification OTP and is not displayed publicly.
- Project Content: We store the data you upload to showcase your work. This includes project titles, descriptions, embedded demo videos, images, Workspace tags, and the text of your posts.
- Collaboration Data: We store information regarding your applications to projects, manual collaboration invitations, and the endorsements you write for or receive from other users.
B. Authentication & Third-Party Credentials
- OAuth Data (Google/GitHub): If you register using a third-party provider, we receive your email address, name, and a unique account identifier (sub/ID) to authenticate you securely.
- GitHub Personal Access Tokens (PAT): To power the native Code Viewer, you may provide a GitHub PAT.
- Strict Scope Limitation: We mandate that you provide a token with only the public_repo scope.
- Storage: We encrypt this token at rest. We never use this token to access, read, or modify your private repositories, nor do we push code on your behalf. You can revoke this token from your GitHub settings at any time.
C. Automatically Collected Technical Data
- Log & Device Data: Our infrastructure providers automatically record IP addresses, browser types, operating systems, and request timestamps to ensure security, prevent abuse (e.g., rate-limiting API requests), and diagnose technical issues.
- Cookies & Local Storage: We use essential cookies and local storage (e.g., state caches) to maintain your authentication session, preserve UI preferences, and manage routing. We do not use third-party advertising or tracking cookies.
2. How We Use Your Data
We process your data strictly to operate and improve the Ovuge Platform:
- Core Functionality: To render your profile, display your projects in the global feed, and manage your Workspace collaborations.
- AI Processing & Snapshots: We utilize automated serverless functions (powered by AI models like Gemini) to extract metadata and generate project snapshots (tags, summaries) from the git trees of your linked public repositories. We only process public code data for this purpose, based on your explicit consent granted during the project upload flow.
- Security & Verification: To prevent bot registration, enforce rate limits, and ensure that users joining specific Networks actually belong to those institutions.
- Notifications: To send you essential push notifications (if opted-in) or email alerts regarding collaboration requests, project updates, and account security.
3. Data Storage and Infrastructure Sub-Processors
To provide a high-performance, secure platform, we utilize trusted cloud infrastructure partners (such as Amazon Web Services and Google Cloud Platform). We may share necessary technical data with these providers strictly for hosting and operating the Platform:
- Database Infrastructure (PostgreSQL): We use robust PostgreSQL databases for our primary backend. Your data is encrypted at rest (industry-standard AES-256) and in transit (TLS/HTTPS). We utilize strict data-access and row-level security policies to ensure that your private data (like settings and draft applications) is inaccessible to other users.
- Cloud Hosting Providers: Our frontend, backend logic, and user-uploaded content are hosted on secure, industry-leading cloud platforms to ensure high availability and reliability.
- Content Delivery & Security Networks: We utilize global content delivery networks (CDNs) and security proxies to optimize website load speeds, deliver media efficiently, provide DDoS protection, and prevent malicious scraping.
These sub-processors are legally bound to strict data protection standards and do not have the right to use your data for their own marketing purposes.
4. Your Rights and Data Control
Depending on your location (e.g., under GDPR or CCPA), you have fundamental rights regarding your data:
- Access and Portability: You can view the data associated with your profile and projects at any time via your dashboard.
- Correction: You can update your profile information, links, and project details directly through the UI.
- Deletion (Right to be Forgotten): You may delete individual projects, withdraw from collaborations, or delete your entire Ovuge account. Deleting a project immediately removes it from the database and public feeds.
- Revocation of Consent: You can disconnect your GitHub repository or revoke your PAT at any time, which will disable the native Code Viewer for that project.
5. Security Measures
We implement robust, industry-standard security measures, including:
- Encryption: Data is encrypted in transit using HTTPS/TLS and at rest in our databases.
- Zero-Trust Architecture: We use strict server-side validation and database-level security rules to ensure users can only mutate data they own.
- Token Security: We do not store raw, unhashed passwords. OAuth and PAT credentials are encrypted and isolated.
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
6. Children's Privacy
Ovuge is designed for college students and adult software developers. We do not knowingly collect personal information from children under the age of 13 (or the applicable legal age in your jurisdiction). If we become aware that we have collected such data, we will take immediate steps to delete it.
7. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our technology or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of the Platform after such modifications constitutes your acknowledgment of the updated policy.
8. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
contact@ovuge.com